# Monitoring ingress pipelines

**URL:** <https://discuss.elastic.co/t/monitoring-ingress-pipelines/283823>\
**Category:** Elasticsearch\
**Tags:** ingest-pipeline\
**Created:** [September 9, 2021, 9:49pm UTC](https://discuss.elastic.co/t/monitoring-ingress-pipelines/283823 "2021-09-09T21:49:53Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Russell\_Fulton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/russell_fulton/32/62888_2.png) [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Post date:** [September 9, 2021, 9:49pm UTC](https://discuss.elastic.co/t/monitoring-ingress-pipelines/283823/1 "2021-09-09T21:49:53Z")

</div>

version 7.14

I have just started trying to use an ingest pipeline on some indices produced by winlogbeats. There are two indices because there are two different versions of the agent.

I have a very simple pipeline with a single drop that matches event.code == 3 (network connections). I have tested it in Kibana against documents from both indices and it works as expected.

The first index I applied it to worked fine but I when applied it to the second index and nothing was indexed at all! Worse still when I removed the setting from the index there were no documents added to the index.

I have confirmed ( with tcpdump) that data is still being sent to that index and (usual provisio) "nothing else has changed"™

I have tried to force the index to rollover without success -- I assume that the rover check is done when data is added to the index.

Is there anyway that I can monitor what the ingest pipeline is doing?

Any other thoughts on diagnosing what is going on.

---

<div class="post-metadata">

**Author:** ![Russell\_Fulton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/russell_fulton/32/62888_2.png) [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Post date:** [September 11, 2021, 5:03am UTC](https://discuss.elastic.co/t/monitoring-ingress-pipelines/283823/2 "2021-09-11T05:03:44Z")

</div>

I think I have finally figured out what the problem was. Very simple as always -- I had failed to add the "ingest" role to one of the ES servers.

It really is a unhelpful failure mode. The really puzzling thing was that as soon as I removed the pipeline clause (after several hours of no logs being indexed) they "magically" appeared. In hindsight winlogbeats must have go failures and stashed the logs.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 9, 2021, 5:03am UTC](https://discuss.elastic.co/t/monitoring-ingress-pipelines/283823/3 "2021-10-09T05:03:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
